2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24460 | HIGH | 7.8 | 0.2% | May 16, 2024 | Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated ... |
| CVE-2023-40297 | HIGH | 7.5 | 1.0% | May 15, 2024 | Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component. |
| CVE-2023-5938 | HIGH | 8.9 | 0.7% | May 15, 2024 | Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable ... |
| CVE-2023-5936 | HIGH | 7.8 | 0.1% | May 15, 2024 | On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a mali... |
| CVE-2023-5935 | HIGH | 7.4 | 0.2% | May 15, 2024 | When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process.... |
| CVE-2023-6324 | HIGH | 8.8 | 0.7% | May 15, 2024 | ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity |
| CVE-2023-6322 | HIGH | 8.8 | 0.8% | May 15, 2024 | A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE ver... |
| CVE-2023-6321 | HIGH | 8.8 | 2.7% | May 15, 2024 | A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to ... |
| CVE-2023-33327 | HIGH | 8.8 | 0.5% | May 14, 2024 | Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This is... |
| CVE-2023-46714 | HIGH | 7.2 | 1.4% | May 14, 2024 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 ... |
| CVE-2023-45583 | HIGH | 7.2 | 0.7% | May 14, 2024 | A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, Forti... |
| CVE-2023-44247 | HIGH | 7.2 | 1.3% | May 14, 2024 | A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker... |
| CVE-2023-40720 | HIGH | 7.1 | 0.8% | May 14, 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug... |
| CVE-2023-46280 | HIGH | 8.2 | 0.3% | May 14, 2024 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All ve... |
| CVE-2023-35841 | HIGH | 7.8 | 0.4% | May 14, 2024 | Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which a... |
| CVE-2023-49781 | HIGH | 7.6 | 0.6% | May 14, 2024 | NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability... |
| CVE-2023-47712 | HIGH | 7.8 | 0.2% | May 14, 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due ... |
| CVE-2023-47709 | HIGH | 8.8 | 1.0% | May 14, 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary comman... |
| CVE-2023-46870 | HIGH | 7.3 | 0.4% | May 14, 2024 | extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Blu... |
| CVE-2023-38264 | HIGH | 7.5 | 0.8% | May 14, 2024 | The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21... |
| CVE-2023-26566 | HIGH | 8.6 | 0.7% | May 14, 2024 | Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which a... |
| CVE-2023-40490 | HIGH | 7.8 | 0.3% | May 7, 2024 | Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2023-35757 | HIGH | 8.8 | 0.6% | May 7, 2024 | D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulne... |
| CVE-2023-35749 | HIGH | 8.8 | 0.6% | May 7, 2024 | D-Link DAP-2622 DDP Firmware Upgrade Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln... |
| CVE-2023-35748 | HIGH | 8.8 | 0.6% | May 7, 2024 | D-Link DAP-2622 DDP Firmware Upgrade Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now